src: update checkpoints to match v0.18.5.0
What changed, and why it matters
This commit updates Monero's built-in blockchain checkpoints to match the v0.18.5.0 release. Checkpoints are hardcoded trusted block hashes that help nodes quickly verify they are following the correct chain and protect against certain attacks. The change is routine release housekeeping: it advances the latest checkpoint from block 3,609,000 to block 3,661,900, updates the binary checkpoint data file, refreshes the expected hash of that file, and updates the README's recommended version table. There is no code logic change and no indication of a security vulnerability being fixed.
No security action required. Treat as a routine release synchronization commit. Users running v0.18.5.0 will automatically use the updated checkpoints. Operators on older versions should plan upgrades per normal Monero release guidance, but this commit itself does not indicate an urgent security fix.
Security signals we found
Hardcoded checkpoint data updated to a newer block height and hash
Expected hash of compiled-in checkpoint blob refreshed
README version guidance updated to v0.18.5.0
No logic or validation code changes present in the diff
Evidence from the diff
The commit modifies four files. README.md updates the ‘Maximum’ recommended version for v15/v16 hard forks from v0.18.4.6 to v0.18.5.0. src/checkpoints/checkpoints.cpp replaces the last ADD_CHECKPOINT2 entry (block 3609000) with a new checkpoint at block 3661900 plus its hash and cumulative difficulty. src/blocks/checkpoints.dat is a regenerated binary checkpoint blob. src/cryptonote_core/blockchain.cpp updates expected_block_hashes_hash to match the new checkpoints.dat content. These are all data-only updates tied to a normal software release; no consensus rules, validation logic, or cryptographic handling changed.
Changed components
src/checkpoints/checkpoints.cppsrc/blocks/checkpoints.datsrc/cryptonote_core/blockchain.cppREADME.mdInspect captured patch +4 / −4
diff --git a/README.md b/README.md
index 480e7ae..d4d0406 100644
--- a/README.md
+++ b/README.md
@@ -137,8 +137,8 @@ Dates are provided in the format YYYY-MM-DD. The "Minimum" is the software versi
| 1978433 | 2019-11-30 | v12 | v0.15.0.0 | v0.16.0.0 | New PoW based on RandomX, only allow >= 2 outputs, change to the block median used to calculate penalty, v1 coinbases are forbidden, rct sigs in coinbase forbidden, 10 block lock time for incoming outputs
| 2210000 | 2020-10-17 | v13 | v0.17.0.0 | v0.17.3.2 | New CLSAG transaction format
| 2210720 | 2020-10-18 | v14 | v0.17.1.1 | v0.17.3.2 | forbid old MLSAG transaction format
-| 2688888 | 2022-08-13 | v15 | v0.18.0.0 | v0.18.4.6 | ringsize = 16, bulletproofs+, view tags, adjusted dynamic block weight algorithm
-| 2689608 | 2022-08-14 | v16 | v0.18.0.0 | v0.18.4.6 | forbid old v14 transaction format
+| 2688888 | 2022-08-13 | v15 | v0.18.0.0 | v0.18.5.0 | ringsize = 16, bulletproofs+, view tags, adjusted dynamic block weight algorithm
+| 2689608 | 2022-08-14 | v16 | v0.18.0.0 | v0.18.5.0 | forbid old v14 transaction format
| XXXXXXX | XXX-XX-XX | XXX | vX.XX.X.X | vX.XX.X.X | XXX |
X's indicate that these details have not been determined as of commit date.
diff --git a/src/blocks/checkpoints.dat b/src/blocks/checkpoints.dat
index a5e8ff3..5b8f04c 100644
Binary files a/src/blocks/checkpoints.dat and b/src/blocks/checkpoints.dat differ
diff --git a/src/checkpoints/checkpoints.cpp b/src/checkpoints/checkpoints.cpp
index 5240af8..2d12180 100644
--- a/src/checkpoints/checkpoints.cpp
+++ b/src/checkpoints/checkpoints.cpp
@@ -270,7 +270,7 @@ namespace cryptonote
ADD_CHECKPOINT2(3516300, "fa08acbcda99fcc3cd94a749364a29fa6de9501a023cb6673d0c68fdf988b7c3", "0x738f0af4d65d459");
ADD_CHECKPOINT2(3541000, "74c457bed9ceef40f31f43bb8fab804077519d45c910dcad2acf4dd8556195c7", "0x76ff158c682d218");
ADD_CHECKPOINT2(3576000, "5da4891bfd06be270193bd949f2a623a2b0cb0ebfaad21c70a6cb18e418e5b6a", "0x7cb2e203e867b57");
- ADD_CHECKPOINT2(3609000, "2c49c7eb40959b4d7a452dcec64e65c59a8b1ebec12ffe0af42bc9468eddae56", "0x823db8bb8f45661");
+ ADD_CHECKPOINT2(3661900, "ac392757a92123f68d63cd72f0d1410f63df1102a53b5d39fc4d53d0998b20a3", "0x8a38f2195826a97");
return true;
}
diff --git a/src/cryptonote_core/blockchain.cpp b/src/cryptonote_core/blockchain.cpp
index 387bae9..433eb6a 100644
--- a/src/cryptonote_core/blockchain.cpp
+++ b/src/cryptonote_core/blockchain.cpp
@@ -5435,7 +5435,7 @@ void Blockchain::cancel()
}
#if defined(PER_BLOCK_CHECKPOINT)
-static const char expected_block_hashes_hash[] = "e60d8cd6d77f55df0874bddc4e0e1c7e387374b95180aa5f172bc83abc7cb799";
+static const char expected_block_hashes_hash[] = "3aed3b6b896e8c1f97802b65f84966526d1ac8d75f417e5ce666f31a5928ac3f";
void Blockchain::load_compiled_in_block_hashes(const GetCheckpointsCallback& get_checkpoints)
{
if (get_checkpoints == nullptr || !m_fast_sync)
Why this scored 22/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.